Hi and welcome to the Stephan Livera podcast focused on Bitcoin and Austrian economics. Today we are carrying on with the hardware wallet interview series, but first, let me introduce the sponsors of the podcast. Check out Kraken, one of the world's leading Bitcoin exchanges. I'm really impressed with the way they operate. They are known for having a really strong focus on On security with Kraken Security Labs, they also act ethically in the space, supporting organizations such as Coin Center. They're one of the longest standing Bitcoin exchanges, and they're consistently rated the best. They've got a high quality platform offering the best liquidity in the industry. They've got high trading volume and low fees, with no minimum or hidden fees. Kraken have twenty four seven support, and on the institutional and business solutions side, they are providing the best in class accounting, reconciliation, and reporting services for cryptocurrency hedge funds. Asset managers and fund administrators. Kraken have an OTC desk for those high attached large block trades. They offer five fiat currencies and also offer margin and futures trading. To learn more and sign up, go to the Kraken link in the show notes. Next up, Unchained Capital. These guys are doing Bitcoin financial services and they've got two main products. One is the Vault and the other is the Bitcoin collateralized loan. So the Vault is a two of three keys multi-signature vault, so you can use Trezor or Ledger. It's really easy to set up, it's all guided through a web interface and you can distribute your keys. And on the Bitcoin collateralized loan side, you can get USD liquidity without selling bitcoins, meaning you don't trigger a capital gains event. So while that loan is outstanding, it's stored in a dedicated multi-signature address under what's called collaborative custody. So if you wanna learn more about that, go to the Unchained Capital link in the show notes. So with that said, we are carrying on with the hard- Hardware wallet interview series today with Charles Guillemet, Chief Security Officer of Ledger, and he's also leading the Ledger Donjon team, which is a hardware security and ethical hacking team. So he has a very impressive background working in hardware security, so there's a lot we can learn from this interview. We talk about what goes into hardware wallet security, what are the crucial components that must be done well, we talk about example hardware wallet attacks and how these are done and how they can be protected against, and also just in case you're having trouble. Following along because it's technical material, just a reminder that I've also got episode transcripts on my website stephanelivera dot com on each episode page, so you can feel free to read along while you listen or even use the transcript as a resource for later on. Here's the interview. Charles, welcome to the show!
TRANSMISSION SLP103
Hardware Wallet Security and Hacking at Donjon Ledger
with Charles Guillemet
Charles Guillemet, Chief Security Officer of Ledger, and also leading Ledger Donjon, joins me to talk about Bitcoin hardware wallet hacking. We talk about the attacks possible, the cost of these attacks, and defence against these attacks. You won’t want to miss this episode!
Hi Stephan, thanks for having me. I'm very happy to be part of the show. I heard the first few episodes about hardware wallets, that was very interesting, many contested, opinions, and I'm gonna to, gonna try to share my views on this, topic that I know, quite well now.
Yeah, I'm sure, you do have a lot to share. So let's get a little bit of background on you and how did you get into this world?
Yeah, sure. about me, well, first of all, sorry for my, for my strong accent, I'm French. during my education in France, I studied pure mathematics, computer science, and cryptography. This is, basically my technical background. I've been working in the security and hardware security, specifically, industry from the beginning of my career, a bit more than ten years ago. at first, I worked in a small company in France Which is called, Tempo. This company, design secure element. I started there as an intern and, during my internship, I breacked the security of one of their circuits, using side-channel attacks. So they decided to, keep me, for a few years and I was in charge of the security of, of circuits. After that, I joined, joined the French ITF, and ITF is an Information Technology Security Evaluation Facility. Basically, this is a third-party security evaluation lab, which is officially accredited by, the ANSSI in France. ANSSI is the French security, certification body. And to give an example with secure elements, the circuits are designed for, critical applications such as banking and passports, but before putting the- There's, smart cards on the market, the vendors have to go through an evaluation and certification process. It lasts several months, and at the end of the evaluation, when all the vulnerabilities, which have been found by the IT staff, have been fixed or solved and so on, the certification authority emits a security certificate, and this sec- certificate grants the vendor, to sell the secure element, for critical application. what, what makes, a secut- a security element, this is the security certification basically. I worked there for around four years and I was, leading the lab, and I joined Ledger, almost two years ago as a CISO. basically I'm responsible for, security of Ledger's product, and as you can, i-imagine, this is a huge mission. I created the donjon. The donjon is our internal security, evaluation lab. we are eight security experts coming from the security industry, and, day to day, we try to break our products because, I think this is the only way to, improve the security, of our products. And when we found vulnerabilities or possible enhancements, we work tightly with, the design team. To, improve our product. Our field of expertize, expertise are, quite wide. We have, experience in hardware security, software security, and, and cryptography.
Fantastic. And as I understand, Donjon Ledger doesn't just hack Ledger products, it actually hacks other, even other hardware wallets as well. and there's a bit of a process around working with that other hardware wallet vendor around working with them on if they need to pay Patch that vulnerability.
yes, you're correct. During, the past, years, we basically we spent, most of our time studying our product. This is the, this is, maybe ninety-five percent of our time. but we also, spent some time to evaluate the security of our vendor's product because we use, HSM, for instance, we use secure elements, we use different secrets, so we also evaluate the, their product because our- As we construct a security product from, not from scratch, but with, basic blocks, we have to evaluate them. This is also part of our, our time. And also we, we spend some time to, look at the, the security of the, the, the hardware wallet on the ecosystem, but not only a hardware wallet, basically, security products.
Fascinating. And so can you give us a little bit of a background then? What are some of the basics of Bitcoin hardware wallet security? Security, what does good look like?
well, basically, hardware wallets i-is a physical device to store, your cryptocurrency, si-uh, keys and, to perform transaction, securely. The basic, basic threat model for a hardware wallet, can be simplified into, three main security features. the first one for me is the capability to generate high quality randomness. this is very important, at least for generating your seed. if ever the wallet has a bad quality random, it can have terrible consequences. It, it, this is very simple, but it is, very, very important. the second main security features, for me is probably The hab-the, the a-ability to prove genuineness of the device from the hardware point, point of view and also from the firmware point of view. The hardware wallet must have a secure mechanism for this, and, this is at the utmost, importance. The, the wallet should ensure secure display and secure inputs, for verifying and granting transaction, and these properties can only be granted if, the wa-the wallet has a genuineness and integrity, mechanism. Otherwise, you, you will be ve-vulnerable to sublation attacks, evil maid attacks, and, if basically if an attacker controls the code running of, on your hardware, he basically controls your coin. So this is also a major, security feature And the third main security fe-features is also, very basic. This is the confidentiality of your keys and the seed. The key, are generated and stored, in the device, and they must, remain protected, against remote attacks, but also against physical attacks. that means that the hardware wallets must protect your keys even if your computer is compromised or even if the attacker just stole, your device. For me, the, the threat model of a hardware wallet is very simple, but not very easy to ensure.
Thanks for the breakdown there. So, if maybe if we were to break some of those three components down, what does it take to, as you said, generate high quality entropy and randomness?
Hardware wallets are made with, with IC, with integrated circuit, and inside the circuit, there are often-- there, there is often, TRNG, which stand for a true random number generator. Generator, and this is, this is a specific part of electronics, there are different kind of design, often this is the free oscillators and which ones in parallel and they are sampled at a very specific timing and this A very tiny, source of entropy is, amplified, with, different, different means. But this is often the kind of the design, the kind of design. And you, you can find this kind of circuit in, Secure Element, but also in, general pur-purposed, MCU. In the, in the case of Secure Element, there is, security evaluation which, verifies the, the good quality of the randomness, and also there is There's a mathematical proof which is, required for, security, certification of the randomness.
How about now the second part where you were talking about proving the genuineness of the device? So as you're saying, the supply chain attack, someone may have tampered with your device before it got to you, or the evil maid attack, where, let's say, you're staying in a hotel and the maid takes your device and tampers with it or does something with it, how would you, what, how can a device be protected against that?
I can imagine there are several, kind of mechanism, but basically what, what we would want is, a device which prevents an attacker to, read the memory and write the memory. And if, if you have this basic property, you can put a key, in, a secret key inside, the, the circuit, and you will request the circuit to prove that, it, it actually holds, this key. And if the circuit can't be tampered, with, and- rewritten, the, the, the genuineness can, can be, achieved, using, this kind of mechanism.
Excellent. And then, I think the, this is probably one that everyone wants to know is how, how is it, how difficult is it, and what does it take to keep the confidentiality of your seed and your keys?
so in this case, it, it really depends on your, threat model, what you consider, what you consider and what you don't consider, but, in my threat for remote attacks and, physical attacks. for remote attacks, you have to take care of all your inputs and to be sure they are properly, taken into account. There is no buffer overflow, no stack overflow, no, I would say all, all the, you have to take care of all the software attacks basically, and if you, also consider the physical attacks, threat model, you have to consider, the, the, the hardware attacks like side chan-side channel attacks, fault attacks and, and- And basic, hardware attacks basically.
Also, this is another common point for discussion within hardware wallets world is open source versus closed source models on software and also the hardware. Can you tell us a little bit about how, how do you think about that?
This question is very interesting, and I think this is, is quite fundamental. first of all, I'd like to say that I love the open source approach. I've been working in the security industry for more than ten years, and the us-usual approach in this industry is to keep everything secret.
especially in the hardware security industry, the main reason why, they keep everything secret is they want to keep their technology, advantage. one of the thing which motivated me to join, Ledger is the openness of the platform. yes, you, you-- we all would like to have all the code to be open source, but already the Nano S and the Nano X, now are the only platform, running on a secure element Where you can load your own native code. from the hardware security, industry perspective, it's already a huge gap. Creating the dungeon, we also dec-decided to open source our, our attack tools, which is also clearly disruptive, from the hardware security perspective. But my mission is about security, so let's discuss this question from a security perspective. What we wait from a hardware wallet is clearly security. first, open source allows auditability of your device, but it doesn't, guarantee that relevant people will, audit, your, your device. in the case of the Nano, the circuit and the devices have been evaluated by us, by, but also by several, relevant security evaluation lab. second, if you decide to make your own open source hardware wallet, you'll have no choice but using a general purpose MCU. And from my experience, I can say something, the data from a general purpose MCU can be extracted very easily, so it removes two main security features, in the threat model, the possibility to verify the genuineness of the device and also the confidentiality of, your secret key against an attacker with a physical access. finally, I'd like to go a bit more into the details of open source hardware wallets, what is actually open source and what isn't, because we, we all-- we often think that everything is, open source on, open source hardware wallet, and it's not really the case. So if we look, a hardware wallet schematically, let's consider it's, i-- it's, a chip with each, with each firmware, we have, several layers. The low- First level will be the chip design, then we'll have the chip implementation and manufacturing, and if we go to the software part, we'll have the low-level software, software which is designed by the IC vendor. There is often a bootloader, some, boot primitives, drivers, this kind of code, and if we stop here The three layers are closed source, closed source and kept secret by the, the IC vendors. This is the case for the Seulement, but this is also the case for, general purpose MCU. In the case of the IC vendors, in the, in the case of the settlement, this part are, designed for security and audited, a-but in the case of general purpose MCU, they, they aren't o-audited by anyone basically. If we go a bit higher in the layers, we get the datasheet of the IC. here is the main difference, the secret element, the datasheet is accessible only in the NDA, maybe because, it explains all the proprietary, countermeasure of the IC, how to config- how to configure them and so on. And in the case of general purpose MCU, they are public and, but there are no countermeasure, basically in the general purpose MCU. Thank you. Then we arrive to the actual firmware. Open-source hardware wallets have mostly a monolithic open-source firmware, and only one can, audit it But the, on the other side, the firmware of the Nano S and the Nano X are divided in two parts. You have the operating system, in one side, which is closed source because it uses the proprietary countermeasure of the IC. but the, this firmware is constantly audited by the Donjon, and it has also been, audited and certified, by a third party, laboratory. On the other side, the application running on top of this operating system, like Bitcoin application, Ethereum, our pas-password manager or SSH, application are open source. So sorry for the long explanation. I just wanted to outline that in fact, an open, open source hardware, wallet, there is a small part of the critical layers which are actually open source. also, also our goal is to open source the most part of our operating system, so probably in the next months we'll open source most of our o-o operating system, keeping closed source only the low level part of the OS which, use the proprietary part of the, of the circuit. So I think people defending open source in this particular case are a bit, religious. finally, I w-we would like, what we would like is an open source agreement. And it will solve all the question, but this is a complete other story.
Right. So if I were to summarize that, then there are essentially, there are different layers of this stack, if you will. So you've got the firmware, you, you mentioned the data sheet and the IC, which is at a low level. And as I understand you, then there are certain components of that IC that are under NDA, non-disclosure agreement, with the creator of that product, and the reason being there are certain proprietary countermeasures that they have put in place. With that IC, and then the reason, if you go back up that stack to the OS, the operating system level, there are certain components of that OS that are closed source because they interact back down with that, proprietary countermeasure part within the IC. Would that be a correct summary then?
This is exactly, exactly why, our operating system is closed source for this on-only reason. The, the NDA only concerns, their very, prop-proprietary countermeasure
Which are implemented into the, the secure element. Got it. Okay. I, I'd be really interested to just talk a little bit about some of the pitfalls and some of the past problems and ways that Bitcoin hardware wallets have been hacked. Could you give us just an overview on what are some of the ways that people try to find vulnerabilities? So as you mentioned, there's side channel attacks, there might be a problem with the cryptography, it might be insufficient entropy or randomness. Can you outline some of those for us?
this is the, the, the main, way to attack, hardware wallet basically. and when I joined Ledger, I've been explained that, I, I didn't know very well the, this ecosystem, and I've been explained that some competitors used, general-purpose MCU for, storing their seed. And for me, that was, I was coming from, from the secure element industry, and for me, that was complete, nonsense. I was clearly aware that this kind of MCU were clear- Really, vulnerable for, to many, different attacks. then I created the dungeon, dungeon now our security evaluation lab, and during our creation, we built some tools and we im-implemented the attack, the test bench and so on. And, we spent most of our time to evaluate our product, but we also, spent some time to, evaluate o-others. So we had a look to the other, wallets in the market, mostly by Scientific interest, first, but when we found all those vulnerabilities, we felt, responsible to help, the, other vendors.
Got it. It might be good to break down some of those ideas. I think one of them, and it comes to this asymmetry, the, the idea of the cost to attack versus the cost of defense, and as I understand, you, you have to try to make it so that the cost to defend is cheaper than the cost to attack. How does that play into what- What you do with Ledger and the devices.
Yeah, the, the attack and defense is a cat and mouse game basically. the thing is that if you don't invest, in the defense, the attacker wins at the end, at some point. And this is prece- this is precisely why, we, I mean, the Bitcoin community, have to continue to, invest our time and resources to, improve the security in the ecosystem. And I'm pretty confident that we'll enable to, prevent all these acts. But again, the, the, the, the cost of the defense, is, is not neutral. We, we have to, spend more, a lot of time and a lot of, money to, improve the, the bar for security, in this industry. And the cost of the attacker, it, it really depends what, what you are attacking. if, if the, if the stakes are high, the, the attacker will spend, a lot of money to, to break systems and they will succeed. basically this is a, i-i-if you win more money, breaking a system that it costs you to, break it, attackers will do it.
Right, yeah. So, let's try and break down some of the typical ways that you might analyze these. So as you mentioned, there's side channel attacks. So as I understand, there are different types of those side channels that you may look at. So there's, as I understand, there's power, looking at the variation or the emanation in that power. There's EM radiation, visual, acoustic. Can you help, explain what are some of those and how, how does it work?
side channel attack. So, we, we love this kind of attacks in, in, in the dungeon, and we, we have, a side channel attack test bench, and we-- the idea of side channel attacks is to monitor a physical, measurement of the circuit during its, when, when it runs some code, you can monitor the power consumption, you can monitor the electromagnetic, emanation, you can monitor the sound, you can monitor a lot of thing. what is- This is the most, efficient is often electromag-magnetic emanation or power consumption. So what you, what you will do as an attacker is you will use the, the hardware wallet, for instance, and during its computation, you will record, the power, power consumption, you will get a lot of traces. And you will try to find a correlation between this set of traces and the data which is, handled, if, inside the, the hardware wallet. And if there is such a correlation, there are plenty of techniques, which allows the, the attacker to, retrieve this data. And if this data is a secret key, then, you succeed to mount an attack. we- We, spent some time on the, on the two zero one, implementation of, PIN verification. And, what we, prove is as an attacker, if I steal your device I will try a few PIN values and record the power consumption of the device during the PIN comparison, and only a few power consumption traces, are enough to guess the correct value of the PIN, and then, thus, I, I will be able to access to, to your, funds. we, we did a responsible disclosure, on this one with, with Trezor, and, they patched it, after a few months, and I think that the new implementation is, is- Clearly harder to, to break, regarding, Satoshi's attacks.
Yeah. And so in that example with the PIN, as I understand, there are different countermeasures that a manufacturer may put into place. So one example is I've heard of, exponential decay, right? So every time you try the PIN and you fail, it makes it even longer before you can try it again. What are your thoughts on that versus, let's say, having just a hard limit? This is the maximum number of times you may try to brute force the PIN, otherwise it bricks
Yeah, for instance, in the case of, of Twitter, we have, fifteen tries, I, I think, or sixteen, fifteen or sixteen, and this is already a lot, from, from a side channel perspective, because you can, record the fifteen traces and then try, with the traces, compute the correlation, try to retrieve the correct value of the PIN, and then, use it, on your sixteen trial. So fifteen is already a lot, but, that would, that would, that would, other countermeasure. The DID is to, ensure that the power consumption of the device doesn't depend only on the, on the correct value of the PIN, but on other random, things, for instance. This is a, this is one kind of countermeasure that you, you can put in place. And in security elements, there are built-in, countermeasure against side-channel attacks, which, put a lot of noise, The blockchain solution, this kind of, all, all, all timing desynchronization, this kind of countermeasure.
So I understand there's this concept of profiling, right? So you might, for example, let's say you know a certain device is a commonly used hardware wallet, and you may buy a copy of that hardware wallet, it's o-openly available, right? And you may then use that to try to understand from that oscillogram, okay, what, what value is it, computing at the time that it's, you know, this level? And is that then you're using that profile to then, when you're doing the, if you're trying to do an attack, obviously, you're then comparing it back against the profile that you created earlier. Is that roughly how one way you do it?
Oh, you're, you're completely correct. And in, in this very case, this is exactly, what we did. We, we have, two thousand one, for which we, we will, try a lot of different PIN and we'll record a lot of traces and we will do, a Exactly as in, computer vision, we will train, an AI, to recognize, not, dogs, from a cat on a picture, but, digit equals one or equals nine on the power traces. But this is basically exactly the same thing. We will train, a machine le-learning algorithm to recognize your digits on the, power consumption. So we do that on the device A, for which we know, the correct value of the PIN, and on the device, that we will, steal from, the victim, we will just record a few traces, and we will ask to our machine learning algorithm what's the correct value of the PIN, and the machine learning algorithm will, answer us the most likely value, for these traces, for this one, for this one, and when you combine the, the, the traces, you are able able to guess the correct value of the PIN. On, on this very example, we were able to, to guess the correct value of the PIN, within four tries. So you, you do, four wrong, value of the PIN, and the fifth, is, is the correct one.
Right, yeah, that's really fascinating. and another concept I saw just from doing some reading is this concept of DPA. Is it differential power analysis? Is it, is that, so what's, what's a DPA? What is a DPA attack?
Oh, you, you studied the topic. Yeah, DPA attack is, is the first one which has been discovered, discovered maybe in nineteen ninety-eight. And in this case, this is non-profiled side-channel attacks. That means that you don't do the first step, which consists Existing, understanding how the device, is running. But to, to, to summarize, this is a statistical, process, which allows an attacker, to distinguish what would be the value of, a specific bit of the key
I see, yeah. and f-from a cryptographic point of view, d- is there anything there that changes in terms of which cryptocurrency is being hacked, or is it more ultimately about trying to get at what is the underlying seed within that device? I,
this is just a good question because, on hardware wallets, there, there is the very, moment when you, you are computing, either your public key or, you're computing a transaction And at this very moment, you will use your secret key, and if you are able to measure the power consumption of the device at this very moment, it can give you a lot of information about the key. And this algorithm, will depend on the cryptocurrency. for instance, if you're using Monero, your scalar multiplication will be implemented, using, ED, two fifty-five, nineteen. in, if you're using, Bitcoin, you, you will use SEC P, two fifty-six, curves. And in both case, that won't be the same algorithm, and the sub-- there are some caveats in the implementation which will change the, the properties of the proof of conception and the, the that will ease, the attacker, to, to extract the key. But in the third model of hardware wallets, This is the, the, the attacker, needs to have the value of the PIN, to, to make a transaction. So this is quite unlikely that an attacker would be able to monitor the per-consumption of your device when you are able to, make a transaction. But we also, studied, the, the scalar multiplication of Twizo, and, we proved that it was possible to, retrieve, the secret value of, your Bitcoin key when it computes, the public key from, y-your, your private key. But this isn't that important because, if the attacker is able to monitor this power consumption, that means that he has already your PIN, your, your PIN value. So, that was more- For scientific interest, then, it will have attacks.
Okay, I see. a- another concept that I've heard of, and this may-- I don't know, let me know if this isn't a relevant kind of attack or way that can be done, but there is this concept of fuzz testing. And so, as I understand, when you do fuzz testing, you're trying to-- let's say you've got a certain field, and you start inputting data that isn't meant to go into that field to see if you can get a different response out of the computer. Is Similar parallel here with hardware wallets and fuzz testing.
Yeah, definitely, because, on hardware wallet, there are, interfaces, I mean, software interfaces, you, when you want to make a transaction, you will have to input your transaction to, to the device and, for USB and so on. There are, there are some interfaces, not that much, because, this is, made for this, hardware, few interfaces for security. But as soon as there are interfaces, you have to, ensure that the inputs Correctly, used and there is no buffer overflow and so on. And this kind of properties, can be, checked using sta-static analysis. This is, a good point. It can be checked also by auditing the code, but it can be difficult to, to figure out all in all the code if there is no buffer overflow, for instance. So in, to be more efficient and more, More, to have more confidence there is no, buffer overflow, we implement phasing. And phasing, wh-what you do is, is quite naive. you will, use, your computer to input a lot of different, inputs, random inputs. you will guide the, the phaser in order that the random is, a bit guided, that you, you won't test the same thing, a lot of times. so you will guide, the, the random, in order efficient and the, the further we'll try to, to monitor, and, and, behavior which aren't, planned by the, by the designer. So as soon as you have a crash, it might, it might,
it, it might be because, there is a buffer overflow, but, small bug which can turn into a vulnerability. Because a vulnerab-vulnerability basically this is a bug, which, can be exploited to, to do something, to do an attack. And the fuzzing process will help you to find, bug just randomly.
Right, I see, yeah. And, I guess in terms of these attacks on ledger devices, were ledger devices sort of hardened against these kinds of attacks or what's the thought there?
So what we, what we do, during the, the design process, we try to, to, to do the most, static analysis possible. the Donjon is only We're auditing the code, day to day. We, we find some vulnerabilities, some announcements, some lot of things that you, you can improve the security. And also, we, we have a emulator in order to, to make phrasing more efficiently, and we also do a phrasing. And also, we do hardware attacks to, to be sure that our, our implementation is, secure against an attacker with a physical access to your device.
Got it. And from a code auditing point of view, are you looking Looking there at things like making sure that, let's say, some cryptographic standard has been correctly implemented and that there hasn't been a mistake made in the random number generation, is that, is that the sort of thing that you're looking for when you're doing code audit?
Yeah, this is part of the audit, yes. this is the most important part of the audit. auditing the crypto library, being sure that, if you, it's not, vulnerable to invalid curve attack, invalid point attack, The, that the randomness is correctly used, there is no bias and all, all this kind of vulnerability which, which can be found in, in crypto.
Fascinating. Okay. can you talk us through a little bit around what does a responsible disclosure process look like? So you found the problem, now you take that either to, if it's internal, you take that to your internal team or out to another hardware wallet team. And as I understand, there's obviously some, interesting ethical questions around this because obviously you have to, there's a- Question of how quickly, is the other party going to respond and try to patch that vulnerability? Because in that time, when it's not patched, all the users are vulnerable, right?
as I mentioned before, we come from an industry where vulnerability is a secret for all players. at Ledger and in the Bitcoin industry, there is this, transparency, trans-transparency policy. but it doesn't mean we, we have to- To directly become, blackhat or, or haxat. I mean, in the dungeon, we are a security researcher, and we are more interested by the science, aspect of the thing, rather, rather than the fame or the money. So in my perspective, this industry suffers a lot, from the fear of the security breaches, so acting ethically is the least we can do. So for the vulnerability we found, we, reported, them, directly to the vendor and asked them if they- We were okay that we disclose them publicly at some point. in most, of the case, we agreed with them on a timeframe and so on. In a few case, cases, the vendor didn't, didn't want us to disclose and we decided not to disclose, simply. And, for instance, if we, if we are talking about, the, the worst I would say vulnerability we found on Trezor, which is, the seed extraction technique, basically what we were, able is to, if you have, access physical access to, Trezor One or Trezor T or Keepkey, device. we figure out an, an attack, which allows, an attacker to extract the seed value from, the, the second. The thing is, this vulnerability can't be patched. There is no way to fix it, and that, that means that, any firmware upgr-upgrade won't allow, to, to patch the vulnerability. So what we decided to do is to Disclose it to the vendor in order to, to, they, they figure out, something to, to mitigate the vulnerability. but as the vulnerability isn't fixable, we decided to, to not publish how we do, so in this case, the-- I think this is the most responsible way to, disclose this vulnerability. in this case, users are aware of the attack, so they can choose a way, to mitigate It, but real attackers on the field, won't be able to, to, to use it, for, for bad things, I would say. So it avoids exploitation while it, makes the users aware of the vulnerability. But yes, responsible disclosure are very, very important. we, we want to make sure that the user of our ecosystem, stays safe.
Got it. I'm also curious, as you came from the, more of the secure element world, and as I understand, in, say, banking, they have HSM, hardware security modules. How does the current state of Bitcoin and Bitcoin hardware wallets compare against, say, banking HSM? Do you have a sense of that?
It's, it's difficult to, to compare hardware wallet to HSM. This is, the different things. HSM is more, a basic block for building, more complex application, while an HSM is already, a hardware wallet is already, an application. This is, this is very precise. but you, you are talking about HSM, in, in the, in the past months, as we use HSM and, for the Ledger Vault, for instance, but also, for, for our, our Nano, S and X, in order to, to be sure they are genuine, there is, there is, mutual authentication with an HSM. So we studied, precisely how HSM works, and we, we did a lot of reverse engineering in order to understand everything, a lot
We found, a few vulnerabilities which are quite critical, and we worked tightly with the vendors, to help them, to, to, to patch the vulnerability. this process last maybe one year, we, we, we found them, last year, I guess. And, and we worked, with them in a long process, and, and when everything has been patched, I think it was the case, in the end of, two thousand eighteen, we agreed with, with them, to publish, and they decided they won't, they didn't want, to be mentioned, so we decided to publish anony- anonymously, the, the vulnerability we found, and we hope that will, increase the knowledge of, of HSM study, security study, and improve the secu-the security of the HSM ecosystem. And we, we published them, at STIC, which is a French security conference, and, at Black Hat a few, a few days ago.
Oh, okay, I'm also really interested to ask you around. So obviously you work for Ledger, so I appreciate that, but, what I'm trying to get at here is a question of, what are your thoughts on using specific hardware devices that, let's say, an outsider, if they see it and they know you're using that device, then they know it's probably got Bitcoin on it, compared to this idea of using non-specific hardware? And so one example, you know, if you know Trace Mayer, he talks about this idea of using the Purism laptop and the Glacier protocol. How do you Different methods and, you know, what's your thoughts on that?
Yeah, I know the, the arguments on, non-specific hardware which would be hair-gapped and so on. first of all, it doesn't solve, the physical access problem. if you use a standard laptop I mean, the attack, if the attacker has a physical access, you lose your farm. so also implementing your own wallet with a laptop isn't an easy task. I mean, there are a lot of companies, on the market which spend a significant time and money and effort, to, to do hardware wallet or, or wallet, and as you can see, it's not easy. So, if you want to build your own hardware, your own wallet, I would say, you, that you We'll have some difficulties to, to make it well. nevertheless, I, I can, I think it's a good idea to implement your own wallet, because, it will help you to understand Bitcoin and how it works and so on. I think it's a good idea. I wouldn't recommend, a non very advanced user to, to do that, because there are plenty of mistakes that you can do, in the process.
Yeah, I see. and so I guess that also ties into the next question around future directions with hardware wallets. what, what's your thoughts on, what they will look like and, you know, what sort of hardware would they use?
It's, it's difficult to, to predict the future and, at, at Ledger, it's not exactly my scope. this is more the mission Of our, CTO, Nicola, Nicola Bacca, that, you, you probably know. and nevertheless, we, we want to be part of the mass adoption, this is, this is part of our mission at Ledger. So, according to me, the mass adoption will only be possible if the user experience is as smooth as possible. for instance, we would like to enable, payments in Bitcoin, with a user experience, similar to contactless banking cards. This is, this is the kind of thing we, we would like to do. the other big challenge is the security of course, and we'll have to, constantly raise the bar for security. we can't lose this, cat and mouse game.
Yeah, that makes, total sense to me. in terms of, oh, sorry, there's one other question I wanted, I was keen to ask about, and this is around, verification of change addresses and the other multisig devices in that set. So let's start with the change address one. So, my, it's my understanding that with some of the ledger devices, potentially in the past, or potentially even now, I'm not sure, there was a, there was a difficulty for the user to make sure Yes, my device holds the private key for this change address. can you speak to that?
I think you are referring to, multisig setup, right?
Yes, I think it's in a, in the case of a multi-signature setup.
So about multisig, first of all, I'd like to say that I love, cryptography, I'm fond of, the schemes. but multisig is a wide field. there are secure MPC with the recent, threshold signatures paper and the older, older- One like Schnorr signature that we will have in Bitcoin soon, I hope so. but, but here, I think you're more talking about the script-based, multisig, used in Ethereum or, or, or more, most likely, PSBT for Bitcoin. so, just a word about security, I heard this trend saying that multisig is the ultimate solution of, to all of our problems. in partic-in particular, I heard, Michael, with who you, you discus-discussed recently. well, okay. Multi-se- multi-signature, schemes need to, to be reviewed by scientific communi- community, and their implementation is also of concern. this is the, the first thing I would say, I would like to say, the main problem, is that a tiny mistake that can lead to massive loss and at scale, and this, this is a, this is a, this is a very concerning to me. And when I saw the some companies, who are basing all their security on a brand new MPC, scientific artifact Article which hasn't even been, reviewed by, the scientific community. I think it's, it's, it's a bit irresponsible. And I don't even talk about, implementation issues. there are already examples of flaws in Ethereum and others, but talking more, more, precisely about, PSBT, on hardware wallet setup, which was your, your initial question, if I understood it correctly. again, I think multi-signature adds, complexity and- And complexity is the enemy of security. so if you really want to use, multi-signature using hardware wallet, you have to be aware of what you do and what are the threats. It's not the magic thing, that Michael was talking about, from my perspective. So talking about our bluebell, our implementation, we are currently, currently, we're working on a full, redesign of the Bitcoin app, and we'd like to include additional, validation based on On, descriptors and pre-validated, templates, and I think it will improve the, the UX and, and the security as well. But waiting this, I, I'd like to, to give some recommendation for the advanced user who would like to, use, multi-sig setup, p-with PSBT and their, their Nano, devices. first of all, the, multi-signature address, addresses must be, validated, using an external channel. the main problem is that there is no straightforward way to validate the public keys that you're, combining are legitimate because, they, they aren't, in your wallet, so it's, it's already a problem. So Validating the addresses must be done on using an external channel, another channel basically. We also recommend to, validate the change addresses through, an external channel. the change question is not simple because it depends on template and only validating the addresses on the device isn't sufficient. it can work only if all parties, comply with, the Bib forty-five and, all the standards. we- Which, which is not, sure, basically. I, I, I want to get into the all these details too. I don't want to lose our, people hearing us. But what, what I want to highlight here is that the, the security of PSBT multisig scheme isn't straightforward, and I won't recommend you, to use it if you don't know exactly what you are doing. And in all case, all case, I suggest to start using it on testnet and try Experiment and, understand everything. I, I, that would be my, my advices about, about multisig and PSBT setup.
Great. Yeah, no, thank you for that. I, yeah, I think, yeah, I guess while we've spoken about some of the ways in which hardware wallets can get hacked and so on, do you have any advice for the listeners out there? Let's say they're an individual, they're using maybe a single signature, single hardware wallet scenario, what, what are some tips and things that they should keep in
yeah, sure. let me recall the basic security advices, because I, looking our, look- looking at our customer support, I, I would say that they, they aren't well understood by everyone. the first one will be, to operate your wallet in a secure environment, especially when you are generating your own seed. don't do that on, on the street, do, do, do that, at home. we, we, we, in, in the quiet place, take your time and so on, it's very impant, it's very important. Don't forget to backup your seed. we have too much customers, who lost their funds because of this, and, and this is a, this is a very, dumb, mistake. And backup your seed securely. I mean, don't take pic-picture of it, don't save it online, on, on your online computer, don't send, send it to you by email So much, time so that there are too much stories of people losing their, their seed just because of this. And the, the last very simple, advice is trust only the display of your Nano, don't trust what is, written on your computer because your computer is, probably, malware. you can also use your, a passphrase for, plausible deniability, for instance, but if you do that, don't lose it. that was the, the very basics, but I think it's important to, recall them.
No, I think that's a totally great reminders for my listeners. how about, do you have any advice for, let's say, people who are operating in a, maybe they're more of a family scenario or maybe they're an institution? Do you have any suggestions on security tips for them?
Okay, if It isn't, institution, institution aren't exactly the same, but, for institutional, storage, I think the best option, on the market so far is the Ledger Vault. I, I will do some, advertising, sorry for this. But, but Ledger Vault is a very, interesting solution from a technical perspective, which is what interests me, but also, in, in the case of, institutional storage, it allows the organization to, manage their funds according to, their, their requirements. The Ledger Vault, brings a very high level of, security. The security of defense relies on, two main pillars. From one side, the hardware security module, which we audited extensively. And, from the other side, on the personal security device, the, the PSD. it allows the customers to define sets of rules and code to, for managing, defense. for instance, they can, there is administrators and, they can decide that, for specific code, This co-op can only, make a transaction of an amount, of, x Bitcoin during a specific period, and if they want to do that, they will have to, make, three signatures out of five using the PSD. But what, what, what is flexible, is that they can decide exactly what are their, requirement, what, what, what is, their governance, basically. It's, it's very flexible, and, while being very secure, since it relies on, secure hardware, the PSD and, the HSM, but also, on cryptography. There is a lot of cryptography between the PSD and the, the hardware security module and, And that's the basicity. And if you are, an advanced user and you, you have a lot of coins, you can, have a look to a multisig setup, but again, I won't, won't recommend, Simple user, I mean, if you're not an advanced user, I don't recommend, you to, to, to go to this setup.
Got it, I see. with the Vault, actually, I, I don't know a huge amount about it. I had a, I had a quick look on the website. so understand then, you were mentioning the PSD devices. It's, but that's not- That's not like multi-signature though, right? That, like, it's more like the, they're calling back to the vault, which is being run out of. Is it a web interface for that? Or what's, what is that?
So it's more a multi-authorization, setup than, than a multi-sig. we, we don't do, multi-sig on-chain, using the PSD. w-what we do is a governance layer which allows multi-authorization, using the PSD. Each PSD Here are the secret key and so on, and the, the HSM, layer will, verify that we, we, indeed have, three out of five people validating this transaction. what, what is very interesting in this setup is that you can Use the, multi-authorization, disregarding, the cryptocurrency you use. You don't have to, to have, a script or to have a, a Schnorr signature. It will work on, Bitcoin exactly the same way, the same way as it will work on Ethereum and Monero and whatever you-- whatever cri-- cryptocurrency, you will have.
Right, I see. Yeah. So it's not using multi-signature, it's more like the authentication into Ledger's vault and then- The vault is the one that's enforcing the policy in terms of three out of five quorum or whatever the quorum that you set, right? Exactly.
You can see, you can see it as a multisig setup be-because what you-- when you're talking about authentication, there is a signature, provided by each PSD, but at the end, that, that this is not on-chain multisignature, this is the main difference, yes.
Yeah. And so those PSDs, are they internet connected or are they sort of like a hardware wallet, but they're just Device for the purpose only of this Ledger Vault.
They, they are based on the Blue, Ledger Blue hardware wallet. So, this is the same platform, but this is very specialized for, Vault application. You can't, install the Bitcoin app, for instance. You just have one app, which is, the Ledger Vault app, and, and this is, this is a Ledger Blue, basically, yes.
Got it. Okay, great. Well, thanks for that, information. I guess lastly, where can the Donjon Ledger.
Yeah, you can follow me on, on Twitter, you have just to search, for, Charles Guillemet, or you can follow the Donjon, our Twitter handle is, Donjon Ledger, and, we have also a blog post, a blog, which is, ledger, ledger dot dash donjon dot github dot io.
Fantastic, I'll, include the links in the show notes for the listeners, but, that was, really great discussion. Thank you
I hope you found that educational and that you're now a little more equipped in terms of knowledge about Bitcoin hardware wallet security. So think about what steps you need to take to improve your own security and just be aware of some of the common mistakes. So make sure you back up your seed, ensure you don't take digital copies of that seed, and be careful what environment you initialize and use the hardware wallet in. And so now you can advise your newbie Bitcoiner friends or better yet, share this episode with your friends so they can learn too. Just a reminder show notes, episode transcript, and podcast subscription links are on my website, stephan livera. Thanks for listening, and I'll see you guys in the Citadelles.